Effective: August 28, 2026 · Version 1.1
Otherlay Kft., a company registered in Hungary, operates the Otherlay dedicated Mac infrastructure service. We are the data controller for account and billing information. For customer content stored on allocated Macs, we act as a data processor.
Contact: privacy@otherlay.eu
Account and billing data is used to: provision and deliver the Service, process payments, send invoices and service notifications, provide support, and comply with legal obligations.
Telemetry data is used to: monitor Mac health and availability, display fleet status in the Console, detect hardware failures, and plan capacity.
Access logs are used for: security monitoring, fraud detection, usage analytics (aggregated, anonymized), and debugging.
Landing-page availability requests are retained for up to 180 days, and next-generation product-interest signals for up to 365 days. We send an operational acknowledgement with a private management link so you can withdraw the request earlier. Completed, failed or suppressed one-shot availability records are removed no later than 90 days after terminal processing. Minimal email-delivery suppression records include the address, failure reason and originating template; they are retained for up to 180 days after a hard bounce or up to 365 days after a complaint or provider suppression, then deleted automatically.
Account deletion has a seven-day cancellation window. After that window we revoke account access, permanently remove online customer content including stored object versions, and anonymize records that must be retained for accounting, security, or support purposes. Current outer retention limits are seven years for financial and tax records, one year for security and audit records, and 30 days for support metadata.
Encrypted disaster-recovery database backups are isolated from the live service and may remain for up to 366 days. They are not used for normal access. Any restoration must reapply later account-deletion records before the restored system may serve production traffic.
We process Customer Content only to deliver features you request, operate encrypted storage, provide customer-authorized support, enforce security where required, or comply with law. We do not train machine learning models on your data. We do not sell or rent your data.
We share data only with:
All subprocessors are bound by data processing agreements with equivalent privacy protections. A current list of subprocessors is available on request.
Customer workloads and primary service storage are hosted in Budapest, Hungary. Account, communication and payment data may be processed by contracted subprocessors in the European Economic Area or in other jurisdictions using an applicable GDPR transfer mechanism, such as an adequacy decision or Standard Contractual Clauses. A current subprocessor list is available on request.
Under the GDPR, you have the right to: access your personal data, correct inaccurate data, request deletion ("right to be forgotten"), restrict or object to processing, data portability, and withdraw consent where processing is based on consent.
To exercise these rights, contact privacy@otherlay.eu. We respond within 30 days. You also have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
The Console uses strictly necessary cookies for authentication and request protection (HttpOnly/Secure session cookie and a CSRF cookie). The website also stores your theme, language and privacy choice locally so the interface and your consent decision persist.
Optional measurement is implemented with Basic Consent Mode: Google Analytics 4, Google Ads and Microsoft Clarity tags do not load and no data is sent to those providers until you grant the corresponding category. You can accept all, reject all optional processing, choose analytics and advertising measurement separately, or withdraw your choice at any time through “Privacy settings” in the website footer.
We configure GA4 event-level retention to 2 months. Microsoft documents 30-day retention for playback data and up to 9 months for heatmap, click, labeled or favorited data. Provider-held aggregate reports may remain for the period configured in the relevant service. Google and Microsoft may process this data outside the EEA under their applicable transfer mechanisms. Optional measurement is based on your consent, which you may withdraw without affecting the lawfulness of earlier processing.
We implement technical and organizational measures to protect your data: encryption in transit (TLS 1.3), encryption at rest (FileVault on all managed Macs), access controls, audit logging, and regular security reviews. In the event of a data breach affecting your personal data, we will notify you within 72 hours of discovery.
We may update this Privacy Policy from time to time. Material changes are communicated by email and in the Console at least 30 days before taking effect.
Otherlay Kft. · Budapest, Hungary · Privacy contact: privacy@otherlay.eu